You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Kubernetes:同集群Pod间HTTPS通信及Apache证书配置方法

Got it, let's break this down into actionable steps for getting your Apache-based Pod2 set up with HTTPS for intra-cluster communication with Pod1 using the internal domain backend-srv.area.cluster.local. I’ll cover both an automated, production-ready approach and a simpler manual method for testing:

Cert-Manager is the de facto tool for managing TLS certificates in Kubernetes—it handles issuance, renewal, and rotation automatically, which is perfect for long-term cluster operations.

Step 1: Install Cert-Manager (if not already present)

You can install it via Helm for simplicity:

helm repo add cert-manager https://charts.jetstack.io
helm repo update
helm install cert-manager cert-manager/cert-manager --namespace cert-manager --create-namespace --version v1.13.0 --set installCRDs=true

# Verify the installation completes successfully
kubectl wait --for=condition=available deployment --timeout=600s -n cert-manager cert-manager

Step 2: Create a Self-Signed ClusterIssuer

Since we’re dealing with an internal cluster domain, a self-signed issuer will work perfectly. Create a ClusterIssuer manifest:

apiVersion: cert-manager.io/v1
kind: ClusterIssuer
metadata:
  name: selfsigned-cluster-issuer
spec:
  selfSigned: {}

Apply it with:

kubectl apply -f cluster-issuer.yaml

Step 3: Request a Certificate for Your Internal Domain

Create a Certificate resource targeting your domain. Make sure the namespace matches where Pod2 is deployed:

apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
  name: backend-srv-cert
  namespace: area # Match Pod2's namespace
spec:
  secretName: backend-srv-tls # Cert-Manager will store the cert in this Secret
  issuerRef:
    name: selfsigned-cluster-issuer
    kind: ClusterIssuer
  dnsNames:
    - backend-srv.area.cluster.local
    - backend-srv.area.svc.cluster.local # Optional but adds redundancy
  privateKey:
    algorithm: RSA
    size: 2048

Apply it with:

kubectl apply -f backend-cert.yaml

Step 4: Mount the Certificate Secret to Pod2 (Apache)

Update Pod2’s Deployment/StatefulSet to mount the TLS Secret into Apache’s certificate directory. Here’s an example Deployment snippet:

apiVersion: apps/v1
kind: Deployment
metadata:
  name: apache-backend
  namespace: area
spec:
  replicas: 1
  selector:
    matchLabels:
      app: backend
  template:
    metadata:
      labels:
        app: backend
    spec:
      containers:
      - name: apache
        image: httpd:2.4
        ports:
        - containerPort: 443
        volumeMounts:
        - name: tls-cert
          mountPath: /usr/local/apache2/conf/ssl/ # Adjust to your Apache cert path
          readOnly: true
        - name: apache-ssl-config
          mountPath: /usr/local/apache2/conf/httpd.conf # Mount custom SSL config
          readOnly: true
      volumes:
      - name: tls-cert
        secret:
          secretName: backend-srv-tls # The Secret from Cert-Manager
      - name: apache-ssl-config
        configMap:
          name: apache-ssl-config # We'll create this next

Step 5: Configure Apache to Use HTTPS

Create a ConfigMap with Apache’s SSL-enabled configuration:

apiVersion: v1
kind: ConfigMap
metadata:
  name: apache-ssl-config
  namespace: area
data:
  httpd.conf: |
    LoadModule ssl_module modules/mod_ssl.so
    Listen 443
    <VirtualHost *:443>
        ServerName backend-srv.area.cluster.local
        SSLEngine on
        SSLCertificateFile /usr/local/apache2/conf/ssl/tls.crt
        SSLCertificateKeyFile /usr/local/apache2/conf/ssl/tls.key
        
        # Add your existing Apache config (document root, routes, etc.) here
        DocumentRoot "/usr/local/apache2/htdocs"
        <Directory "/usr/local/apache2/htdocs">
            AllowOverride None
            Require all granted
        </Directory>
    </VirtualHost>

Apply it and restart the Apache deployment to load the new config:

kubectl apply -f apache-config.yaml
kubectl rollout restart deployment apache-backend -n area

Step 6: Make Pod1 Trust the Certificate

Since this is a self-signed cert, Pod1 needs to trust its CA. Mount the CA cert (from the same backend-srv-tls Secret) into Pod1’s trusted certificate store. For a Debian/Ubuntu-based Pod1, update its Deployment:

# Add this to Pod1's Deployment spec
volumes:
- name: trusted-ca
  secret:
    secretName: backend-srv-tls
    items:
    - key: ca.crt
      path: backend-ca.crt
volumeMounts:
- name: trusted-ca
  mountPath: /usr/local/share/ca-certificates/
  readOnly: true

# Update the container command to refresh trusted certs on startup
command: ["/bin/sh", "-c"]
args: ["update-ca-certificates && <your-existing-startup-command>"]

Restart Pod1, and it’ll now trust Pod2’s HTTPS endpoint.

Method 2: Manual Self-Signed Certificate (For Testing/Simple Setups)

If you don’t want to use Cert-Manager for a quick test, you can generate and mount certificates manually:

Step 1: Generate a Self-Signed Cert Locally

Use openssl to create the cert and key:

openssl req -x509 -newkey rsa:2048 -keyout backend.key -out backend.crt -days 365 -nodes -subj "/CN=backend-srv.area.cluster.local" -addext "subjectAltName=DNS:backend-srv.area.cluster.local,DNS:backend-srv.area.svc.cluster.local"

Step 2: Create a Kubernetes Secret for the Cert

kubectl create secret tls backend-srv-tls -n area --cert=backend.crt --key=backend.key

Step 3: Mount and Configure Apache

Follow steps 4 and 5 from Method 1 to mount the Secret and configure Apache’s SSL.

Step 4: Trust the Cert in Pod1

Same as Method 1’s Step 6—mount the backend.crt (since it’s self-signed, this acts as the CA cert) into Pod1’s trusted store.

Quick Notes

  • Ensure your backend-srv Service exposes port 443 for HTTPS traffic.
  • Cert-Manager will auto-renew certificates before they expire, which is why it’s preferred for production.
  • For production, if you need publicly trusted certs (unlikely for internal services), you can configure Cert-Manager to use Let’s Encrypt instead of a self-signed issuer.

内容的提问来源于stack exchange,提问作者mostworld77

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 09:09:12